Complete feed
No mitigation yet
No fix, workaround or mitigation extracted yet
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Advisory [CVE-2026-66145] unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip
An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip.
Critical [CVE-2026-13206] Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zyxel Networks WAH7601 allows OS Command Injection
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zyxel Networks WAH7601 allows OS Command Injection. This issue affects WAH7601: through 20072026.
Critical [CVE-2026-28672] Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apache Ranger: from 0.6 through 2.8.
High [CVE-2026-69112] Path Traversal and Denial of Service via weight_map
Path Traversal and Denial of Service via weight_map. Red Hat rates this important (CVSS 7.1). Weakness: CWE-22. Affected products named by the advisory: Lightspeed Core; OpenShift Lightspeed; Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; and 1 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI).
High [CVE-2026-71576] Manager trusts self-asserted evt.Source for leaf-hub identity in all status handlers
Manager trusts self-asserted evt. Source() for leaf-hub identity in all status handlers. Red Hat rates this important (CVSS 8.5). Weakness: CWE-345.
High [CVE-2026-6374] Use of Hard-coded Credentials vulnerability in Zyxel Networks WAH7601 allows Read Sensitive Constants Within an Executable
Use of Hard-coded Credentials vulnerability in Zyxel Networks WAH7601 allows Read Sensitive Constants Within an Executable. This issue affects WAH7601: through 20.07.2026.
High [CVE-2026-12984] Insufficiently Protected Credentials vulnerability in Zyxel Networks WAH7601 allows Retrieve Embedded Sensitive Data
Insufficiently Protected Credentials vulnerability in Zyxel Networks WAH7601 allows Retrieve Embedded Sensitive Data. This issue affects WAH7601: through 20072026.
High [CVE-2026-68415] clear mode callbacks after failed mode setup
clear mode callbacks after failed mode setup. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.
High [CVE-2026-68409] defer link RX stats percpu free to RCU
defer link RX stats percpu free to RCU. Red Hat rates this important (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel.
High [CVE-2026-68404] use wiphy work for socket owner autodisconnect
use wiphy work for socket owner autodisconnect. Red Hat rates this moderate (CVSS 7). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68402] Linux kernel: Wi-Fi subsystem out-of-bounds read via crafted frames
Linux kernel: Wi-Fi subsystem out-of-bounds read via crafted frames. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-68401] Fix out-of-bound writes in ffa_setup_and_transmit
Fix out-of-bound writes in ffa_setup_and_transmit(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel.
High [CVE-2026-68399] Fix UAF in sock clone early bailouts
Fix UAF in sock clone early bailouts. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel-rt.
High [CVE-2026-68398] Linux kernel: PPP over L2TP Use-After-Free vulnerability
Linux kernel: PPP over L2TP Use-After-Free vulnerability. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68397] take a reference on the socket found in afiucv_hs_rcv
take a reference on the socket found in afiucv_hs_rcv(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
High [CVE-2026-68393] extend conn_hash lookup critical sections
extend conn_hash lookup critical sections. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.
High [CVE-2026-68389] Clear memdump state on invalid dump size
Clear memdump state on invalid dump size. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.
High [CVE-2026-68381] Use-after-free vulnerability due to race condition in connection handling
Use-after-free vulnerability due to race condition in connection handling. Red Hat rates this moderate (CVSS 7). Weakness: CWE-364. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68377] Linux kernel: Denial of Service due to use-after-free in act_tunnel_key
Linux kernel: Denial of Service due to use-after-free in act_tunnel_key. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-68376] fix auth_hmacs array size in struct sctp_cookie
fix auth_hmacs array size in struct sctp_cookie. Red Hat rates this important (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.